Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2761+ Articles
166+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
NEWS

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

PaperCut shipped maintenance releases for two actively exploited CVEs after a Russian-speaking actor hit 395 orgs in 48 countries using AI agents.

Dylan H.

Security Engineer

September 11, 2026
2 min read

PaperCut Ships Permanent Fixes After Weeks of Emergency Patching

PaperCut has released regular maintenance updates for PaperCut NG/MF that formally supersede a string of emergency patches issued over the prior weeks to address two actively exploited vulnerabilities. The company says the new releases "contain all of the security fixes issued in Emergency Patch Releases 1, 2 and 3, plus additional security hardening."

The Vulnerabilities

  • CVE-2026-81578 — An authentication bypass affecting PaperCut NG/MF.
  • CVE-2026-82078 — An arbitrary code execution flaw affecting PaperCut NG/MF.

Fixed versions are PaperCut NG/MF 26.0.5, 25.0.13, and 24.1.10. Organizations that applied the earlier emergency patches should still upgrade to these maintenance releases, since they roll in additional hardening beyond the original hotfixes.

An AI-Scaled Attack Campaign

A suspected Russian-speaking threat actor weaponized both flaws to compromise at least 395 organizations across 48 countries, with U.S. educational institutions bearing the brunt of the targeting. Notably, the campaign reportedly used hundreds of AI agents powered by OpenAI's Codex and DeepSeek models to automate exploitation at scale — a sign of how AI tooling is lowering the bar for running high-volume, multi-target intrusion campaigns.

Investigators traced campaign infrastructure to IP address 45.142.193[.]132. The operators notably avoided targeting organizations in Russia, China, Hong Kong, Thailand, Iran, and more than twenty other countries — a common pattern among threat actors seeking to avoid domestic law-enforcement attention.

Why Education Was Hit Hardest

PaperCut's print-management software is deeply embedded in school and university IT environments, often with broad network reach to manage print jobs across labs, libraries, and administrative offices. That footprint, combined with historically under-resourced K-12 and higher-ed security teams, makes the sector a recurring soft target whenever a PaperCut flaw surfaces — this is not the platform's first brush with mass exploitation.

Mitigation

  • Upgrade to PaperCut NG/MF 26.0.5, 25.0.13, or 24.1.10 immediately, even if emergency patches were already applied
  • Review logs for indicators of compromise dating back to August 27, 2026, when the original security advisory was issued
  • Block known malicious infrastructure, including IP 45.142.193[.]132
  • Restrict PaperCut admin interfaces to trusted internal networks rather than exposing them to the internet
  • Educational institutions in particular should treat PaperCut patching as a priority given the scale of targeting observed in this campaign

Source: The Hacker News

#PaperCut#Vulnerability#CVE#AI-Driven Attacks#Education Sector

Related Articles

PaperCut Releases Second Emergency Patch for Exploited Flaws

PaperCut ships Emergency Patch Release 2 for CVE-2026-81578 and CVE-2026-82078 after researchers bypassed the first fix in active attacks.

5 min read

Microsoft Warns of New Defender Zero-Days Exploited in Attacks

Microsoft has issued emergency patches for two Windows Defender vulnerabilities that were actively exploited as zero-days before fixes were available....

5 min read

Recently Patched PaperCut Zero-Days Used in Data Theft Attacks

Attackers exploiting PaperCut NG/MF's patched auth-bypass and RCE chain have pivoted to dumping database tables instead of deploying payloads.

4 min read
Back to all News